<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Vitess</title>
  <link>https://cvedaily.com/pages/tags/vitess.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vitess.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Vitess</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-27969 – Vitess is a database clustering system for horizontal scaling of MySQL. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27969</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27969</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also added to the manifest and backup contents — are written to any accessible location on restore. This i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27965 – Vitess is a database clustering system for horizontal scaling of MySQL. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27965</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27965</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. This can be used to provide that attacker with unintended/unauthorized access to the production deplo…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53257 – Vitess is a database clustering system for horizontal scaling of MySQL. The /deb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53257</guid>
    <pubDate>Tue, 03 Dec 2024 16:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53257</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template instead of rendering with a proper HTML templating engine. This vulnerability is fixed…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32886 – Vitess is a database clustering system for horizontal scaling of MySQL. When exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32886</guid>
    <pubDate>Wed, 08 May 2024 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32886</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-29195 – Vitess is a database clustering system for horizontal scaling of MySQL through g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29195</guid>
    <pubDate>Thu, 11 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-29195</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will receive an error. Attempting to view the keyspace(s) will also no longer work. Creat…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-29194 – Vitess is a database clustering system for horizontal scaling of MySQL. Users ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29194</guid>
    <pubDate>Fri, 14 Apr 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-29194</strong></p>
  <p>Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using `vtctldclient GetKeyspaces` will also return an error. Note that all other keyspaces can still…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29194">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
